Page 2 of 12 results (0.001 seconds)

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 0

31 Aug 2007 — Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name. Desbordamiento del buffer en la función processLine en maptemplate.c en MapServer en versiones anteriores a 4.10.3 permite a atacantes remotos provocar una caída de servicio y posiblemente ejecutar un código arbitrario a través de un mapfile con un nombre largo de cap... • http://mapserver.gis.umn.edu/download/current/HISTORY.TXT • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

27 Aug 2007 — Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in mapserv.c in the mapserv CGI program. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en MapServer anterior a 4.10.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados ... • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439346 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •